Permission denied errors — page 3
Issues 401–600 of the 2,495 matching this topic. The trend chart and topic overview are on page 1.
- Installation Failure on Windows - Unsupported OS Error
- MCP OAuth loopback redirect uses 127.0.0.1 instead of localhost — breaks providers (e.g. Salesforce) that only allow localhost callback URLs
- [BUG] Sandbox masking of nonexistent ~/.claude/.config.json creates a transient empty file visible system-wide; concurrent sessions fail with 'contains invalid JSON'
- Sandbox fails to arm: apply-seccomp setgroups EPERM in initial userns unless allowAllUnixSockets:true (2.1.220)
- [BUG] Context usage percentage computed against 200K while session actually runs with 1M context ([1m] model variant)
- EPERM error after update to 2.1.193
- [DOCS] Sandbox docs omit `sandbox.credentials` setting added in v2.1.187
- WorktreeCreate hook fails with EPERM for repos under ~/Documents — hook spawned via 'disclaimer' shim loses the app's TCC Documents grant
- Support skipping GCP auth in Vertex AI mode for proxy-based deployments
- [Bug] Linked worktree sandbox auto-allow missing main .git directory and denyWithinAllow paths off-by-one
- Plan mode should enforce read-only at the tool layer, not via LLM instruction
- [BUG] Cowork sandbox VM bundle not found in Roaming path on Windows 10 Pro (Store/AppX install) — hardlink workaround
- MCP sandbox egress: allow <us2.make.com>
- macOS: "'2.x.xxx' would like to access data from other apps" prompt on every launch
- [Bug] filesystem.denyRead not merged with Read(...) deny permissions in sandbox
- [BUG] Cowork: Session init fails to mount scheduled task config folder outside project mount after macOS Desktop upgrade
- [BUG] \u in Windows path is interpreted as Unicode escape sequence, corrupting file paths for usernames starting with u followed by hex digits
- [Bug] Auto mode bypasses manual permission prompt for dangerouslyDisableSandbox commands
- [BUG] [P0] Claude Code Web sandbox produces Docker-incompatible projects that fail outside the sandbox!!!
- [BUG] Cowork/Workspace EXDEV: cross-device link not permitted on Windows 11 — rootfs.vhdx rename fails
- [BUG] Write tool bypasses sandbox filesystem write restrictions that Bash tool correctly enforces
- Duplicate detection bot is auto-closing valid issues at scale — 15,240 closures and counting
- [BUG] Paste auth code does not work on v2.1.107 when running claude code in a VM from Mac
- [BUG] Bypassed global settings to read secret keys
- feat: add option to scope /resume to current workspace directory
- [FEATURE] Enable Ruby 3.4+ in claude code web sandboxes
- Sandbox filesystem rules can't scope to git root, breaking worktree workflows
- Documentation discrepancy: Read(...) deny rules affect Bash tool calls (undocumented behavior)
- [BUG] recent seccomp change for /sandbox broke executing Windows tools from WSL
- permissions.allow in project .claude/settings.json is ignored by VS Code extension
- [BUG] Scheduled remote triggers lost gh CLI access
- [DOCS] PowerShell docs omit key permission-check behavior
- You've hit your limit · resets 1am (Europe/London)
- [BUG] sandbox: allowAllUnixSockets does not cover network-bind — tsx and other IPC servers fail with EPERM
- Bug: Sandbox half-broken — writes hit real filesystem, reads sandboxed — destroyed entire project
- [BUG] isolation="worktree" fails on Windows — falsely reports "not in a git repository"
- Plugin system does not preserve execute permission on hook scripts
- [BUG] Plugin .sh files lose execute permission on marketplace update
- [BUG] Cowork "requires a newer installation" on Windows 11 Enterprise 24H2 — yukonSilver unsupported on v1.1.8359.0
- [BUG] Cowork returns 403 on macOS 26.3.1 but works on macOS 26.3
- [BUG] Sandbox blocks CoreSimulator mach-lookup, breaking iOS simulator tests
- [BUG] Windows: Drive Letter Change Triggers Permission Resolver Explosion + Arbitrary .claude/ Directory Creation Outside Workspace
- Voice mode: holding spacebar inserts spaces instead of triggering recording on Linux
- [Bug] Sandbox mode unavailable on macOS - missing platform support
- [BUG] Claude Code sets ~/.claude.json to read-only (444), then hangs on startup because it can't write to it
- [BUG] sandbox Claude Code crashes and OOM-killed by kernel when node_modules exists in project directory
- [BUG] Cowork shows "Virtualization is not enabled" on Windows 11 despite Hyper-V fully enabled (Lenovo ThinkPad)
- [BUG] [Cowork] Windows: EXDEV error on rename during VM bundle setup (EFS-related)
- IDE integration does not work inside Docker Desktop sandboxes
- [BUG] Thinking blocks modification error persists in v2.1.20 (post-Jan 25 fix)
- [Bug] Screen flickering persists in version 2.1.17
- [FEATURE] Use relative path symlink in native installer
- Feature Request: Expose Sandbox Status to Status Line JSON Input
- [BUG] Weekly Limit Not Resetting on time
- Background task fails with EPERM when user lacks write access to drive root
- [BUG] Sandbox debug output contaminating JSON stream in Codespaces
- AWS Bedrock compatibility issue with tools.3.custom.input_examples in v2.0.46
- [BUG] Bash tool error reporting insufficient for chained commands (only "Exit code 1")
- [Bug] Sandbox mode causes 200+ second delay on bash command results
- Path Normalization Failure: Doubled Unix Drive Prefix in Windows Environments
- [BUG] Permission settings unclear/inconsistent - security issues
- [BUG] CRITICAL: Write tool creates files outside working directory on Windows
- Permission denied with aws bedrock but working with aws cli
- [BUG] Cloud environment setup script gets HTTP 503 through the security proxy; the identical curl succeeds when the agent runs it in-session
- [Bug] Sandbox write-deny on `.claude/.cc-writes` prevents git worktree removal after ExitWorktree
- [FEATURE] Forward URL fragments into published artifacts so section deep links work
- Background auto-mode sessions execute Bash calls matching ask rules (and PreToolUse hook ask decisions) without any prompt (2.1.215)
- Atomic write to ~/.claude/settings.json fails with EROFS/EACCES when the file is a symlink-to-a-symlink
- [BUG] Windows MSIX/Cowork: in-app Claude Code writes silently virtualized (succeed but don't persist), and in-place updates deadlock on the Cowork VM service's file handles
- [FEATURE] Multi-dimensional / scientific data visualization in Claude Code (charts, plots, heatmaps — beyond Mermaid)
- Sandbox masks nonexistent deny-listed paths as unreadable device nodes - breaks plain git whenever `extensions.worktreeConfig` is enabled
- [FEATURE] Path anchor prefix for the current project's metadata directory in sandbox filesystem rules
- Regression (2.1.195 → 2.1.196): background daemon transient-spawn fails over SSH on macOS — "Could not switch to audit session: Operation not permitted"
- SSH sessions: history blank and fork fails due to tail connecting via raw IP instead of SSH config alias
- [Bug] Tool-call markup leaks into assistant text after large context accumulation
- [BUG] Cowork sandbox fails to start on macOS after June 10 app update: "Workspace unavailable... Download failed"
- [BUG] Claude Managed Agent internal proxy throwing 503 when interacting with Git
- [FEATURE] VS Code extension: cap chat panel max-width for readability on wide displays
- [Feature Request] macOS sandbox: auto-manage allowMachLookup for TLS/system services
- [BUG] Cowork sandbox: unlink(2) returns EPERM on owned files, breaks .git lock cleanup
- [BUG] IS_SANDBOX=yes and port 27017 blocked on "Full" network access cloud environment
- Hosted GitHub MCP OAuth flow broken in claude.ai/code web sessions
- Long-running synchronous MCP tool calls (>~10–12 min) trigger 'session stopped responding' UI watchdog and orphan MCP server processes
- remote-control 2.1.138 regression: pre-create-session POST returns 400 "Extra inputs are not permitted", phone work-dispatch silently broken
- [BUG] Edit/Write tools fail with EPERM on Windows drive root paths (e.g. D:\)
- [Bug] Agent executes destructive database operations without confirmation, causing data loss
- Improve sandbox support for erlang / elixir
- Sandbox bind-mounts /dev/null device nodes in working directory, breaking Python build tools
- [BUG] Claude code freezes when running in sandbox (WSL)
- [BUG] claude --continue aborts on Linux 2.1.120 with `sandbox required but unavailable: ${j$}` (unfilled template literal)
- sandbox.enabled: false ignored at runtime; allowWrite emits doubled path prefix (2.1.116)
- [BUG] EXDEV on MSIX workspace setup (rootfs.vhdx rename fails) - Win32 workaround from #48362 no longer exists, no fix available
- bwrap launcher uses --bind for optional hardware paths (/opt/cuda*); fails on systems without CUDA installed
- Auto mode hangs silently when a tool call is rejected by sandbox/permissions
- [BUG] Cowork tab missing — yukonSilver misdetection, build 1.3109.0, Windows 11 MSIX
- [BUG] Cowork: "Failed to create bridge sockets after 5 attempts" on every session since 1.3036.0 (macOS 26.3.1)
- [BUG] Code 1
- [BUG] Error text color too dark on dark terminal backgrounds
- [BUG] Sandbox deny rules with mid-path globs cause E2BIG on Linux — per-file bwrap expansion instead of per-directory overlay
- [DOCS] Sandboxing network-access prompt flow is outdated for auto mode and bypassPermissions
- Bundled ripgrep binary loses execute permission on macOS (breaks command/skill discovery)
- [MODEL] Opus 4.6 deleted a git worktree that was actively being used by another claude code session
- [BUG] Claude Agent in Xcode downloads ARM64 binary on Intel Macs, x64 binary rejected due to code signing
- Plugin deployment strips execute bit from hook shell scripts
- [Windows] Background agent output file stays 0 bytes due to symlink permission failure
- Plugin marketplace sync drops execute permissions on .sh files
- Include sandbox state in hook input JSON
- [BUG] dangerouslyDisableSandbox bypasses sandbox without prompting in auto-allow mode
- Desktop app cannot start sessions in ~/Library/CloudStorage (OneDrive/iCloud) paths
- [BUG] Claude Code uses Linux sandbox (bwrap) instead of macOS Seatbelt when bwrap is installed via Homebrew (Apple Silicon, v2.1.71)
- Managed settings deny rules from Console not enforced (remote-settings.json)
- Claude Desktop: disclaimer helper blocked by macOS quarantine - local sessions crash with 'Operation not permitted'
- [Bug] Concurrent config writes corrupt `.claude.json` on Windows startup
- Agent SDK: prompt cache invalidated every query() — random UUID in Bash tool description
- [BUG] Cowork – Virtualization Not Detected on Dell XPS 14 9440 (Windows 11 Pro)
- [DOCS] Permission rule evaluation docs don't match observed behavior (deny → ask → allow precedence)
- [BUG] Cowork Windows - sandbox-helper fails to mount host share (virtiofs/Plan9) with OneDrive-synced folders
- [DOCS] Plugin authoring guide should warn about plugin.json name collision with marketplace name
- [BUG] Claude Code bash tool fails on HPC/SLURM compute nodes
- [Bug] Plugin installation installs all skills instead of selected plugin only
- [Bug] Ctrl+C unable to interrupt long-running Bash commands
- Task tool subagent spawning ignores TMPDIR, hardcodes /tmp/claude/
- [BUG] gradle being blocked by sandbox even though it's dir off of ~ is in the allow list
- [Bug] 80% usage in 2 days - Rate limit usage display shows incorrect percentage for current week/session - Max x20 $200/mo
- [BUG] Termux: Background tasks fail with malformed path - HOME sanitization breaks on deep paths
- [BUG] Glob fails silently when ripgrep hits permission denied on any subdirectory
- [BUG] Shell initialization (cd ~ in .bashrc) breaks workspace boundary
- [TypeScript V2 SDK] Tool execution requires approval despite permissionMode: 'bypassPermissions' and allowDangerouslySkipPermissions: true
- [BUG] Execution of Deny permissions in settings.json
- [BUG] Inline command execution (!`cmd`) in slash commands fails with permission error
- [BUG] Error: EPERM: operation not permitted, uv_cwd
- [BUG] Cowork browser fallback crashes app, leaves it unable to launch ("This app can't open") — recurs even after reinstall
- [BUG] Cowork: VM boots but guest_vsock_connect never completes on Intel Mac — "Direct-boot artifacts not present in bundle", 60s timeout
- CLAUDE_CODE_LOCAL_BINARY override still dead code in Desktop 1.24012.11 (Linux) — initLocalBinary() has no call site; env var is read and discarded
- Cowork sandbox recurring failure — useradd exit 12 / no space left on device (5 recurrences in a week, prior fix didn't hold)
- [BUG] iOS Simulator panel helper (claude-ios-sim) crashes on launch on macOS 27 beta — seatbelt profile blocks Metal's new per-bundle shader-cache directory
- [Feature Request] Increase concurrent workflow agent limit for hosted sandboxes
- Cowork sessions can no longer manage local scheduled tasks: scheduled-tasks MCP not exposed to (now remote-executing) desktop sessions, and the Scheduled folder is blocked as a protected location
- [BUG] Cowork sandbox fails at sdk_install on Windows — VM guest crashes with "connection forcibly closed" (regression SDK 2.1.181 → 2.1.202)
- [BUG] Prompt suggestions silently suppressed whenever the client-derived rate-limit status is allowed_warning — strict-equality gate in Vxy
- [Bug] Claude Code Desktop crashes with EPERM error after Fable 5 suspension
- [BUG] Remote execution sandbox blocks git clone to github.com, breaking pip install of git+https:// dependencies
- [Cowork file tools silently truncate / null-pad writes on the Windows workspace mount]
- [BUG] Cowork (Windows): sandbox mount serves a truncated/stale copy of a file after the user saves it (non-OneDrive local folder)
- [BUG] Cowork: personal GitHub marketplace never updates — clone silently fails, runtime serves stale version despite correct metadata
- Claude in Chrome (MCP): navigate/javascript_tool denied 'Permission denied by user' with no approval popup; approved-sites list can't be populated — survives reinstall + reconnect
- [BUG] No supported way to disable only the context_management beta — breaks Claude Code on HIPAA-flagged orgs without ZDR (first-party Anthropic API)
- settings.json: add user-approval-required mode for dangerouslyDisableSandbox
- [BUG] Cowork VHDX placement fails with ELOOP on Intel RST VMD Controller 467F — distinct from EXDEV, bash permanently broken since v1.8089.1
- [BUG] All Claude in Chrome MCP page-content tools blocked — permission_required / Navigation not allowed, approval UI never renders (related: #53630, #57219)
- [DOCS] REPL and Workflow sandbox protections are undocumented
- [BUG] Security: permissions.deny rules not working
- [BUG] Security: denyRead in sandbox not working
- [BUG] SANDBOX ERROR CODE ENOSPC: no space left on device,
- [BUG] Cowork: Edit silently clamps file size to pre-edit size — data loss, reproduces #52581
- [Bug] Web client OTLP telemetry missing user.account_id, user.email, and organization.id fields
- [BUG] Git proxy returns 403 Forbidden on git-receive-pack
- [Bug] Claude Code exits with code 1 when inline --settings temp file in /tmp is owned by another user
- macOS Tahoe: Claude Code 2.1.132+ writes block all non-Anthropic apps from reading files in ~/Documents (regression vs 2.1.128)
- [BUG] mcp__github__authenticate emits an OAuth URL that redirects to a turned-down Google Drive MCP install page
- [BUG] Claude settings JSON schema does not contain `sandbox.failIfUnavailable`
- [BUG] Bash task/monitor in Sandbox mode creates empty .dotfiles
- Bash sandbox bypassed by subagents via command obfuscation (8/15 agents, zero human approval)
- [BUG] Token drift in parallel Write tool calls: repeated path prefix produces real-word substitution ("shane" → "seine")
- Model re-narrates stale image content from memory; confabulates descriptions matching conversation context after Read tool returns
- [BUG] `/plugin marketplace add <local-path>` registers but plugin installs with 0 skills (workaround: pre-create symlink)
- [BUG] Cowork: VirtioFS mount fails with "operation not permitted" — all projects blocked, regression from previously-working state
- [BUG] [Cowork] Scheduled-task sandboxes cannot mount Drive folder; Drive writes blocked at canonical AND Library/CloudStorage paths
- /ultrareview hangs after 'Claude Code process started' — no review-bug events emitted, 30-min timeout
- [BUG] Sandbox bwrap fails when ~/.nix-profile exists as a symlink to a directory
- Desktop SSH: ccd-cli /tmp/claude-settings-{hash}.json permission collision in multi-user hosts causes exit 1
- Double-Esc (message selector) freezes input dispatch in resumed sessions on macOS
- [BUG] `sandbox.filesystem.denyRead` silently bypassed when target is inside a `denyWrite` directory
- [BUG] Cowork Linux sandbox fails with HYPERVISOR_SERVICE_ERROR (0x80370102) on Citrix XenServer-based VDI environment
- [BUG] sandbox.filesystem.allowWrite does not permit unlink / rm on macOS
- [BUG] `output_config` sent to Vertex AI causes `invalid_request_error` on session title generation
- [BUG] Intermittent "Tool permission stream closed before response received" on Bash tool calls
- [BUG] Cowork scheduled task reads stale filesystem snapshot between invocations (Windows)
- [BUG] origin remote URL corruption via GIT_COMMON_DIR + rbs/ruby-lsp in devcontainer
- Cowork: Failed to create bridge sockets after 5 attempts (v1.3036.0)
- [BUG] Claude commands fail with EACCES permission denied error when creating files
- Scheduled tasks fail with 'useradd: cannot create directory /sessions/...' RPC error
- [BUG] RPC error: ensure user: useradd failed: exit status 12: useradd: cannot create directory /sessions/clever-adoring-planck
- [BUG] $TMPDIR resolves to different paths between sandboxed and non-sandboxed Bash invocations
- Memory system cannot delete files — only create/overwrite
- Sandbox mode leaves read-only bind mounts that persist after disable
- [BUG] Claude in Chrome server-side classification blocks pd.smileynova.com — was working until April 9, 2026
- [BUG] Cowork Windows: EXDEV cross-device rename failure causes machine crashes on bundle update — affects all MSIX installs
- [BUG] Cowork sandbox blocks MCP subprocess connections to Google APIs
- [BUG] All custom slash commands missing from autocomplete on v2.1.89 (WSL2/Linux)
- [BUG] Cowork: Sandbox silently reads truncated/stale file content from mounted folder — no error raised
- Allow /insights to be scoped to a specific project or repo
- bwrap: Can't create file at .claude/skills: Is a directory when sandbox enabled with symlink SSOT structure
- Plugin updater loses execute permission on cached hook scripts
- Cowork will not start
- [BUG] Claude Code silently rewrites user-provided relative path into fabricated absolute Windows path in transcript
- [BUG] Specifying `Edit(filepath)` in `permissions.deny` whilst also specifying the filepath in `denyWrite` for `sandbox` causes bwrap failures on all bash tool calls
- Cowork macOS: VirtioFS mount fails for all folders — "mkdir /mnt/.virtiofs-root/Gerald: operation not permitted"
- Claude Code repeatedly ignores its own auto-memory feedback during sessions
- MCP servers using npx fail to connect in VS Code 1.112